Tags: sqli web rce pwn fuzzing 

Rating: 2.0

Solved by bruteforcing file magic, fuzzing finfo and injecting payload in file metadata to get sql injection in sqlite3 and then RCE.

Original writeup (https://anee.me/file-magician-36c3-ctf-6cb5964c3238).